Remote Code Execution Vulnerability in Internet Explorer on Windows XP and Older Versions
CVE-2004-0839
Currently unrated
Key Information:
- Vendor
- Avaya
- Vendor
- CVE Published:
- 18 August 2004
Summary
A vulnerability in Internet Explorer, specifically in versions such as 5.01 and 5.5, as well as Windows XP SP2, permits remote attackers to execute arbitrary code on users' systems. This can be achieved through specially crafted web pages that leverage specific CSS styles, the AnchorClick behavior, and drag-and-drop features to silently drop malicious executables into the user's local startup folder, thereby executing them upon system startup. To mitigate this issue, users are advised to apply updates from Microsoft and adhere to best practices in web security.
References
EPSS Score
38% chance of being exploited in the next 30 days.
Timeline
Vulnerability Reserved
Vulnerability published